Identify Untrusted CA Certificates (Strata Cloud Manager)
Block sessions with untrusted issuers in the decryption
profile for SSL Forward Proxy.
When you block sessions with untrusted issuers in the decryption profile, the
decryption log records the error.
Select Manage Configuration NGFW and Prisma Access Security Services Decryption.
Under Decryption Profiles, select or Add a new profile, and then
select the Block sessions with untrusted
issuers option.
Filter decryption logs to identify sessions that failed due to revoked
certificates.
Select Incidents and Alerts Log ViewerFirewall/Decryption.
Use the query Error Message = ‘Untrusted issuer
CA’.
(Optional) Double-check the certificate expiration date at the Qualys
SSL Labs site.
Enter the hostname of the server (Server Name
Identification column of the decryption log) in the
Hostname field, and then
Submit it to view certificate information for the
host.